Identity
Passport identity, named owner, lifecycle state, and approved purpose.
CSA AI Controls Matrix
Scaled Agents can help enterprises explain how AI worker identity, access, oversight, monitoring, and human accountability map to a control-oriented review model.
This page is a public alignment summary. It does not claim CSA endorsement, STAR listing, control certification, or that a product page alone satisfies a customer or assessor review.
Context
Control matrices are useful only when they can be translated into accountable records, runtime decisions, and evidence that a customer can actually review.
Scaled Agents focuses on the governed AI worker record chain rather than abstract policy text alone. The customer remains responsible for deciding whether a specific deployed AI system is in scope for any external review.
Current reference status: CSA released AI Controls Matrix v1.1 in June 2026 with 247 control objectives across 18 security domains. This page uses high-level themes only and does not reproduce the matrix. Confirm the current package, mappings, implementation guidance, auditing guidance, and licensing terms on the CSA AICM v1.1 source page.
Control Themes
Passport identity, named owner, lifecycle state, and approved purpose.
Tool and data boundaries, Toll Gates, Runtime Permit decisions, and prohibited actions.
Human Review, escalation, role separation, and customer-managed approval paths.
Stamps, workflow events, evidence records, and audit export composition.
Public Mapping
The matrix below uses general control themes and avoids detailed customer-specific evidence or copied control text.
| CSA AI control theme | Current Scaled Agents capability | Fit | Next improvement |
|---|---|---|---|
| Identity and ownership | Passport owner, role, purpose, lifecycle state, and escalation path. | Strong | Expose assurance profile summaries in customer Passport views. |
| Contextual access control | Toll Gates, tool permissions, Runtime Permit posture, and Action Broker boundary. | Strong | Preserve customer environment evidence alongside public product context. |
| Monitoring and traceability | Evidence records, Stamps, workflow events, and audit export planning. | Partial | Finalize customer-safe assurance export summaries over existing records. |
| Human oversight and review | Human Review, exception handling, and shared responsibility model. | Strong | Link customer reviewer assignments to environment-specific evidence packs. |
Product Fit
Creates named AI worker records with ownership, purpose, boundaries, and review status.
Shows control decisions, evidence, and runtime posture without collapsing review and approval into one signal.
Preserves accountable reviewer decisions, escalations, and exception handling.
Composes customer-safe summaries from existing records instead of inventing a separate evidence system.